Skip to content

write-api: implement POST /api/people/:slug/account-level (administrator-only) #33

Description

@themightychris

Deferred from write-api (PR #29). The plan listed account-level changes under People mutations but didn't ship a dedicated endpoint — the spec at specs/api/people.md calls for POST /api/people/:slug/account-level (administrator-only).

Required pieces:

  • New route + write service
  • Auth: requireAuth('administrator') (NOT 'staff | administrator' — only admin can elevate/demote)
  • Audit trail in the commit message: Action: account-level.change, with Previous-Account-Level + New-Account-Level trailers
  • Validation: cannot demote yourself if you're the only administrator (would lock everyone out)
  • Tests: happy path; non-admin caller → 403; self-demotion last-admin → 422

Activity

  1. added this to the Post-cutover milestone on May 20, 2026
  2. added a commit that references this issue on Jun 30, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions